Practitioner training scenario

Secure the Meridian Health Portal, step by step.

A fictional patient portal used for hands-on assessment practice. Students work the full assessment lifecycle against a single realistic system, producing the same deliverables a real assessment team would.

System owner
David Eggerton
Meridian Regional Health System, IT Services Division
Authorizing official
Dana Okafor
State Health Agency, Chief Information Officer
Users
180,000 patients, 2,400 clinical staff, 60 administrators
Hosting
Commercial cloud IaaS, single region, two availability zones

Seven Sequential Modules

  1. Step 0

    Prepare

    Confirm stakeholders, draw the authorization boundary, designate the common control provider, and state the risk tolerance for Meridian Health Portal.

    Deliverable: Preparation and Stakeholder Package

  2. Step 1

    Categorize the System

    Set confidentiality, integrity, and availability impact levels for each information type, then complete the Privacy Threshold Analysis.

    Deliverable: FIPS 199 Categorization and Privacy Threshold Analysis

  3. Step 2

    Select Controls

    Choose the baseline that matches your categorization, then designate every control as system-specific, inherited, hybrid, or not applicable.

    Deliverable: Control Baseline Selection and Designation Table

  4. Step 3

    Implement Controls

    Write an implementation narrative for each selected control and assign an owner and target date for the work.

    Deliverable: Implementation Narratives

  5. Step 4

    Assess Controls

    Test the implemented controls, record findings with severity, and upload the evidence that supports each result.

    Deliverable: Security Assessment Findings and Evidence

  6. Step 5

    Authorize the System

    Weigh residual risk and issue a signed authorization decision for Meridian Health Portal.

    Deliverable: Authorization Decision Memo

  7. Step 6

    Monitor

    Set the ongoing reassessment cadence for each control family, work the open POA&M items, and report the current security posture.

    Deliverable: Continuous Monitoring Report